STIGQter STIGQter: STIG Summary: Ivanti EPMM Server Security Technical Implementation Guide Version: 3 Release: 1 Benchmark Date: 24 Oct 2024:

The Ivanti EPMM server must be configured to lock an administrator's account for at least 15 minutes after the account has been locked because the maximum number of unsuccessful login attempts has been exceeded.

DISA Rule

SV-251777r1004741_rule

Vulnerability Number

V-251777

Group Title

SRG-APP-000345-UEM-000218

Rule Version

IMIC-11-008520

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the Ivanti EPMM server to lock an administrator's account for at least 15 minutes after the account has been locked because the maximum number of unsuccessful login attempts has been exceeded.

Log in to the Core Admin Console >> Settings >> Security >> Password Policy.
Set "Auto-Lock Time" to 15 minutes (900 seconds).

Check Contents

Verify the Ivanti EPMM server has been configured to lock an administrator's account for at least 15 minutes after the account has been locked because the maximum number of unsuccessful login attempts has been exceeded.

Log in to the Core Admin Console >> Settings >> Security >> Password Policy.
Verify "Auto-Lock Time" is set to 15 minutes (900 seconds).

If the Ivanti EPMM server does not lock an administrator's account for at least 15 minutes after the account has been locked because the maximum number of unsuccessful login attempts has been exceeded, this is a finding.

Vulnerability Number

V-251777

Documentable

False

Rule Version

IMIC-11-008520

Severity Override Guidance

Verify the Ivanti EPMM server has been configured to lock an administrator's account for at least 15 minutes after the account has been locked because the maximum number of unsuccessful login attempts has been exceeded.

Log in to the Core Admin Console >> Settings >> Security >> Password Policy.
Verify "Auto-Lock Time" is set to 15 minutes (900 seconds).

If the Ivanti EPMM server does not lock an administrator's account for at least 15 minutes after the account has been locked because the maximum number of unsuccessful login attempts has been exceeded, this is a finding.

Check Content Reference

M

Target Key

5445